CVE-2023-35311 — Microsoft Outlook Security Feature Bypass Vulnerability
2023-07-11 • CISA Known Exploited Vulnerability
[event] Microsoft Outlook contains a security feature bypass vulnerability that allows an attacker to bypass the Microsoft Outlook Security Notice prompt.
> AFFECTED SOFTWARE
| Field | Value |
|---|---|
| Vendor | Microsoft |
| Product | Outlook |
| CWE | CWE-367 |
| CVE ID | CVE-2023-35311 |
| Date Added | 2023-07-11 |
| Due Date | 2023-08-01 |
| Ransomware Campaign | Unknown |
> MITIGATION
Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.
Due Date: 2023-08-01